PicaCAN: Reverse Engineering Physical Semantics of Signals in CAN Messages Using Physically-Induced Causalities
Yucheng Ruan, Chengcheng Zhao, Zeyu Yang, Yuanchao Shu, Peng Cheng, Jiming Chen · IEEE Transactions on Mobile Computing · 2025
With the rapid development of Connected and Autonomous Vehicles, In-Vehicle Network attacks have garnered heightened research scrutiny due to vehicles’ increasing connectivities to the external environment. The common characteristic among these attacks is to tamper with targeted powertrain-related signals in the Powertrain Controller Area Network (PT-CAN) and further physically threaten vehicles’ safety. These powertrain-related signals are encoded within CAN messages grounded by the syntax specification, which is proprietary to Original Equipment Manufacturers and publicly unavailable. Thus, to undertake comprehensive security analysis and strategies, reverse engineering PT-CAN to the semantic level is urgently needed. However, the existing methods rely on interactions (injecting challenge signals/actions) with the targeted vehicle, and certain manual efforts are required. To fill this gap, we proposePicaCAN, a novel framework to extract signals from CAN messages and reverse engineer their physical semantics based on physically induced causality. Once access to the CAN traffic,PicaCANoffers the researcher an eye on the vehicle’s powertrain system, decoding binaries flows into powertrain-related signals automatically. We experimentally evaluatePicaCANon PT-CAN of three automobiles containing two power types. The experimental results show thatPicaCANcould successfully extract physical signals representing all targeted semantics (pedals, engine speed, etc.) from two Internal Combustion Engine Vehicles and one Hybrid Electric Vehicle under EV mode.